19
That one firewall config review that split my brain in half
Honestly, my buddy at a fintech shop in Austin told me they run every rule change through a peer review process, even the urgent ones. He said their last emergency patch got rolled back twice because the reviewer caught a CIDR overlap that would've killed their PCI segment. It hit different because I've always pushed for speed over process, claiming that slow reviews just delay fixes. But seeing his team's data on 14 incidents in the last year where review caught issues before prod makes me wonder if we're being reckless. For those of you managing critical infra, do you have a hard rule for mandatory peer review on all firewall changes, or do you still allow a bypass for 'break glass' scenarios?
0 comments
Log in to join the discussion
Log In0 Comments
No comments yet
Be the first to share your thoughts on this discussion.